Skip to main content
Back to home

Subprocessors

Last updated: May 14, 2026

The third-party service providers ("subprocessors") that Chask uses to operate the Service. For full context, see our Privacy Policy — this page is the authoritative source for who receives what data.

Current subprocessors

OpenAI

Purpose:
LLM provider for goal breakdown, planning, milestones, chat, and content generation. Models: gpt-5.3-codex, gpt-4o, gpt-4o-mini.
Data shared:
Goal content, task descriptions, chat messages, About-me profile context, persona traits (when enabled), milestone structure, scheduling windows, story extracts.
Processing location:
United States
Transfer mechanism:
Standard Contractual Clauses; OpenAI API customer data is not used to train models by default.

Supabase

Purpose:
Primary database, authentication, real-time, and file storage.
Data shared:
Account profile, goals, tasks, milestones, journal notes, workspace data, OAuth tokens (encrypted at rest).
Processing location:
United States (AWS)
Transfer mechanism:
Standard Contractual Clauses

Sentry

Purpose:
Error monitoring and performance tracing.
Data shared:
Stack traces, request paths, IP address, browser metadata, Chask context tags (UUIDs). Authorization headers, cookies, and goal/NLP request bodies are scrubbed before send.
Processing location:
United States
Transfer mechanism:
Standard Contractual Clauses; EU-US Data Privacy Framework

PostHog

Purpose:
Product analytics (opt-in only). Autocapture and session recording are disabled.
Data shared:
Aggregated feature-usage events, page views, opt-in event metadata.
Processing location:
United States or European Union (depending on cluster)
Transfer mechanism:
Standard Contractual Clauses; EU-US Data Privacy Framework

Google (Calendar OAuth)

Purpose:
Calendar integration: read and write events you authorize.
Data shared:
OAuth refresh and access tokens (encrypted at rest with AES-256-GCM); calendar event payloads you authorize.
Processing location:
United States; Google global infrastructure
Transfer mechanism:
EU-US Data Privacy Framework; Standard Contractual Clauses

Stripe

Purpose:
Payment processing and subscription management.
Data shared:
User ID, workspace ID, selected tier, billing amount, Stripe customer ID. Card numbers are never sent to Chask.
Processing location:
United States
Transfer mechanism:
Standard Contractual Clauses; EU-US Data Privacy Framework

Resend

Purpose:
Transactional email delivery (verification, password resets, account notifications).
Data shared:
Recipient email address, sender, subject, message body.
Processing location:
United States
Transfer mechanism:
Standard Contractual Clauses

Redis-compatible cache

Purpose:
Short-lived caching of AI responses to reduce LLM calls (default TTL 30 minutes).
Data shared:
Request keys derived from input parameters; generated AI outputs.
Processing location:
United States (co-located with primary infrastructure)
Transfer mechanism:
Internal infrastructure; no third-party transfer

Notification of changes

We update this page whenever we add, change, or remove a subprocessor. To receive change notifications by email, contact privacy@chask.ai with the subject line "Subscribe to subprocessor change notifications".

For Data Processing Agreements with Chask, email legal@chask.ai.